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Abstract 

The relativistic quantum protocols realizing the bit commitment and distant coin tossing schemes 
are proposed. The protocols are based on the fact that the non-stationary orthogonal extended quan- 
tum states cannot be reliably distinguished if they are not fully accessible for the measurement. As 
the states propagate from the domain controlled by one of the user to the domain accessible for the 
measurements performed by the other user, they become reliably distinguishable for the second user. 
Important for the protocol are both the quantum nature of the states and the existence of a finite 
maximum speed of the signal propagation imposed by the special relativity. 
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1 Introduction 



Many cryptographic problems reduce to a number of primitive cryptographic exchange protocols, such 
as the secret key distribution [1-3], bit commitment [4-6], and distant coin tossing [7] protocols. The bit 
f-*- ■ commitment protocol is stronger than the distant coin tossing one in the sense that a distant coin tossing 
protocol can be formulated on the basis of a bit commitment protocol. 

Informally, the bit commitment protocol is usually formulated in the following way. The protocol 
involves two participants (users) called A and B. At the commitment stage the user A chooses the value 
of a secret bit (0 or 1) and sends some information about his choice to user B in such a way that using 
the information provide by user A the user B cannot reliably determine the secret bit value chosen by A. 
To be more precise, in the ideal case the probability for user B to correctly identify the bit value chosen 
by user A is exactly 1/2 (i.e. it is equal to the probability of simply guessing the bit value) regardless 
of whether or not he uses the information supplied by user A. Then at the disclosure stage the user B 
can ask user A to provide him the rest information on the value of the chosen secret bit so that in the 
ideal case the user B reliably recovers the secret bit value. In addition, there should be no possibility 
for user A to change his mind and alter the chosen bit value after the commitment stage and before the 
^ ' disclosure state without being caught by user B. 

The distant coin tossing protocol is formulated in the following way. The two distant users A and 
B, who do not trust each other and can employ any physically realizable opportunities to cheat, should 
exchange appropriate information so that at the end of the protocol (in the ideal case with the unit 
probability) they accept the arising bit as an honest lot. If the users have only access to the classical 
communication channel, the problem can even seem unsolvable. 

Obviously, realization of any bit commitment protocol can be used to construct a distant coin tossing 
protocol. To achieve this purpose, user B can try and guess the bit chosen user A after the commitment 
stage but before the disclosure stage (remember that after the disclosure stage the secret bit chosen 
by user A is publicly known). The user B wins if he guesses the bit value chosen by user A and loses 
otherwise. 

The following protocol is sometimes described as a simple example of the bit commitment protocol. 
User A writes down the chosen bit value on a paper sheet and places it into a safe which is then sent 
to user B (commitment stage) without the key which is only given to user B at the disclosure stage. In 
spite of the simplicity of the above example, it contains all the basic features of the protocols based on 
the classical information carriers. In this example, the user B obtains the complete rather than partial 
information on the secret bit at the commitment stage. Therefore, the laws of nature do not prohibit the 
user B to learn the secret bit value even before the disclosure stage if he has access to sufficient technical 
resources. A similar situation takes place in the protocols based on the computational complexity of 
some trap- functions (e.g., discrete logarithm) [8]. In the protocols of that type user A announces to 



user B the value y (where y = a b mod p; a,p are known in advance, and the parity of b is the secret bit 
value). In principle, the supplied information on bit b (i.e., the value of function y) is sufficient to learn 
the secret bit by calculating the discrete logarithm. However, all available classical numerical algorithms 
require exponentially large computational resources (although it was never proved that there exists no 
more efficient polynomial classical algorithm for this problem). 

For the case where A and B can only exchange information through the classical communication 
channel, the problem was solved in Ref. [8]. Strictly speaking, the protocol proposed in Ref. [8] is not 
secure against cheating by one of the users since it is based on the unproved computational complexity 
of the discrete logarithm problem [8] . 

In these protocols the user B is given the complete rather than partial information on the secret bit 
already at the commitment stage. Therefore, in principle, user B can learn the secret bit even before the 
disclosure stage, for example, by using the quantum computer [9,10] (which is currently, however, very 
far from the experimental realization). 

Employing only the classical (non-relativistic) objects as the information carriers, it is impossible to 
construct an unconditionally secure bit commitment protocol (whose security is based on the fundamental 
laws of nature only rather than current technical limitations) where only "part" of a classical object (for 
example, a spatially extended signal which is only partly accessible to user B before the disclosure 
stage) is supplied to user B at the commitment stage. Since the part of the signal available to user 
B until the disclosure stage should have the same appearance to user B for both values and 1 of 
the secret bit (otherwise the user B will have non-zero information about the secret bit before the 
beginning of the disclosure stage), the part of the classical object which is left with user A should be 
different for different secret bit values. The laws of classical non-relativistic physics do not prohibit an 
instantaneous modification of the part of the signal still controlled by user A converting into 1 or vice 
versa before submitting it to user B immediately before the disclosure stage thus allowing cheating by user 
A. therefore, no unconditionally secure bit commitment protocol can be realized within the framework 
of non-relativistic classical physics. 

In the non-relativistic quantum protocols the information is carried by quantum systems. Schemati- 
cally, the protocols can be described in the following way. First, the Hilbert state space 7i s is chosen to 
which the states of the information carriers belong. User A choses the states |Y>o,i) £ T~ts, corresponding 
to or 1 and send them to B. The states are usually chosen to be non-orthogonal. It is important that the 
state space TL S is implicitly assumed to be fully accessible to both users A and B throughout the entire 
protocol. The requirement that the density matrices corresponding to both and 1 look identically for 
user B until the disclosure stage begins results in the possibility of an undetectable cheating by user A 
employing an EPR-attack [11,12]. Roughly speaking, in this approach the protocol involves only the state 
space of the quantum system. However, this situation actually does not correspond to the real process of 
information transfer. To be more precise, we mean the following. The participants of the protocol cannot 
control the entire space. Instead, they control only certain domains (vicinities of their laboratories, mea- 
suring devices, etc). In addition, all the measurements occur in the real space and time (or space-time 
in the relativistic case). The non-relativistic quantum mechanics allows construction of entangled states 
of physically different systems (we are only interested in this case because it is impossible to perform a 
measurement which affects only one of the two identical systems). Therefore, if the users control only 
the non-overlapping domains, the entangled state from 7i s <S> 7i a should automatically be non-local also 
in the coordinate space. The wave functions of both systems from 7i s and 7i a should be simultaneously 
different from zero in the domains controlled by users A and B (because otherwise the state will not be 
entangled for the users). The latter means that each user has access to both state spaces, 7i s and H a , 
and can perform measurements and unitary transformations separately over both systems at his own 
discretion due to their physical distinguishability. Therefore, the locality of the transformations in the 
state space TL S ® TL a (in the sense of manipulation in only one of the state subspaces) does not imply 
the locality in the coordinate (position) space. In other words, in the non-relativistic quantum protocols 
of that kind (when the spatio-temporal structure of the information carrier states is not explicitly taken 
into account) the state space of the information carriers is accessible by both users. In this sense such 
protocols do not realize the idea of submitting only a part of information on the carrier of a secret bit. 

In the non-relativistic case, explicit accounting for the effects of state propagation in the position 
space, when user B has access to only a part of a spatially extended state, can hardly introduce any new 



aspects to the indicated problems because of the absence of the maximum propagation speed. 

Formulation of the problem where only the properties of the state space TC are used does not corre- 
spond to the actual process of information transfer in the real space-time. It is more natural to consider a 
problem when the users are located in their respective laboratories and control some their spatial neigh- 
borhoods. It is natural to assume that neither A or B can control and have access simultaneously the 
entire space. 

The state propagation effects (accounting for the spatio-temporal structure of the quantum states) 
were first explicitly used in quantum cryptography in Ref. [13] (which, in our opinion, was not assessed 
correctly [14,15]). Accounting for the restrictions imposed by the special relativity and quantum mechan- 
ics (quantum field theory) [16] substantially simplifies the proof of unconditional security of relativistic 
quantum cryptosystems [17]. Besides, the quantum field theory introduces additional fundamental re- 
strictions, e.g. on the teleportation of quantum states [18]. 

Recently, the classical bit commitment and distant coin tossing protocols have been proposed which 
take into account the existence of finite maximum speed of signal (information) propagation [19]. The 
relativistic classical protocol [19] is unconditionally secure (i.e. its security is based on the fundamental 
laws of nature only) and in principle allows to delay the second stage of the protocol (disclosure of the 
secret bit value chosen by A) for arbitrarily long time. The implementation of this protocol requires that 
each of the users A and B control two spatially separated sites. 

The idea of using orthogonal states in the bit commitment and coin tossing protocols was proposed 
earlier in Ref. [20]. The protocols suggested in Ref. [20] were based on two simple considerations. First, a 
pair of orthogonal (and, consequently, reliably distinguishable when completely accessible) states become 
efficiently non-orthogonal (only partly distinguishable) when restricted to a subspace. This is also true 
in non-relativistic quantum mechanics. Indeed, if we have a pair of spatially extended orthogonal states, 
ipo,i(x) G £ 2 (— oo, oo, dx) 



they become effectively non-orthogonal when restricted to a subspace (a finite domain f2 in the position 
space) : 



The second important consideration is the existence of a finite maximum speed of both quantum states 
propagation and classical objects motion implied by the special relativity. This fact does not allow to 
instantaneously access the entire state (i.e., the domain where the state is present). 

In contrast to Ref. [20], where the state had no "internal" degrees of freedom, taking into account the 
states with "internal" degrees of freedom (e.g. helicity for photons) allows to substantially simplify the 
protocols. 

To be more precise, the states for ^0,1) = VK^O® l e o,i) ((eo|ei) = 0) and 1 are orthogonal (due to the 
internal degrees of freedom) even if they only partly accessible for the measurement (i.e. the measuring 
apparatus can access only a part of the entire spatial domain where ip(x) 7^ 0); however, in that case they 
are not reliably distinguishable: the probability of distinguishing between these two states (probability of 
obtaining a measurement result in one of the orthogonal channels) can be made arbitrarily small if only 
a part of the state is accessible since the probability of obtaining an outcome in a finite spatial domain is 



so that by appropriately choosing the domain size and function ip(x) the probability can be made arbi- 
trarily small (which actually follows from the normalization condition J^L. \ ip(x)\ 2 dx = 1). 

Schematically, our protocol can be described in the following way. User A controls a finite spatial 
domain and prepares a quantum state in it at the moment specified by the protocol. This state propagates 
into the quantum communication channel and becomes gradually accessible to the user B in the spatial 
domain which is not controlled by user B. Having access to only a part of the quantum state in the real 
position space, user B cannot reliably determine the secret bit (reliably distinguish between and 1). 
Moreover, it is possible to choose the states in such a way that the probability of correct determination 
of the secret bit by user B is arbitrarily close to 1/2 (i.e. simple guessing probability) for arbitrarily 






long (although agreed upon before the start of the protocol) time interval. There exist no fundamental 
restrictions on the length of this interval, although making it long enough may present a difficult technical 
problem. The existence of a finite maximum propagation speed allows to choose the states in such a way 
that the user A can no longer modify the chosen bit value after the prepared state has partly left the 
domain controlled by him. After the protocol duration time elapses and the states sent by user A become 
completely accessible to user B the latter acquires reliable information on the states with the probability 
arbitrarily close to 1. Important for this protocol are both the quantum nature of the states involved 
and the existence of a finite maximum speed of propagation imposed by the special relativity. 

The states and measurements used in the protocols are described in Section 2 while the bit commit- 
ment and coin tossing protocols themselves for the states with finite supports are presented in Sections 
3 and 4, respectively. The fundamental non-localizability of quantum states in the quantum field theory 
is accounted for in Section 5. The main results obtained in the paper are summarized in Conclusions. 



2 States and measurements used in the protocol. 

Since the protocol explicitly employs the spatio-temporal structure of the states, it cannot be formulated 
without specifying the system geometry. We shall consider a one-dimensional model containing all the 
important features dictated by the quantum field theory; a similar model is frequently used in quantum 
optics. We shall deal with a massless field whose states in the momentum representation are specified 
on the mass shell k^ — k 2 = 0. Important for us are the states propagating in the positive direction of 
x-axis (k > 0). We assume that user A controls a neighbourhood of point xa, while user B controls a 
neighborhood of point xb (xa <xb)- 

In the following all functions are assumed to depend on the difference r = t — x; the speed of light 
is assumed to be unit, c = 1. This representation reflects the intuitive picture of a packet moving with 
the speed of light. The momentum eigenstate \k), corresponding to the eigenvalue A; is a generalized 
eigenvector (to be more precise, a linear continuous functional on the elements from a dense subset in 
H = £ 2 (0, oo, c££)) and has the form 

m = s(k-o- (i) 

The states \ip) from H can be expanded in the generalized states 

POO 

|V) = / <A#)|fc)dfc, (2) 
Jo 

where the value taken by the functional (k\ on the element |V>) is 

roo 

(k\^) = / ^)S(k-0d^ = ^(k), 
Jo 

i.e. the amplitude of the state \tp) in the /c-representation. Accordingly, the amplitude of the state \k) in 
the r-representation is 

(k\r) = -^L=e lfcr , fce(0,oo), r G (-oo, oo), r = t - x, (3) 

corresponding to the intuitive picture of a plane wave (a state with a definite momentum) moving with 
the speed of light. 

It will be important for the protocol that the quantum states propagate with the maximum possible 
speed of light. In the r-representation the orthogonal states (packets) corresponding to and 1 used in 
the protocol are written in the form 

/oo 
/(r)|r)dr(8) |e ,i), (e |ei) = 0, (e ,i|e ,i) = 1, (4) 
-oo 

where the states |eo,i) describe the internal degrees of freedom (e.g. helicity for photons). 
The state normalization condition takes the form 



/oo poo 
/ f(T)f*(T')(T\T')dTdT' = l, 
-oo J —oo 



(5) 



yields 



where 

(r\r') = ±5 + (t -t>) = ±- f° e ik ^dk = U{r - r') + (6) 

Z7T Z7T JO 2 IT T — T 

We shall introduce the state amplitude in the /c-representation defined as 

roo 

f(r) = / f(k)e~ ikT dk. (7) 
Jo 

Then taking into account Eqs. (5-7) the normalization condition becomes 

roo roo 1 ?' 1 

(iMlM = / / /«f(r')[^(r " r') + -——\drdrr'. (8) 

J —oo J ~oo ^ 7T T T 

Substitution of the state amplitude in the /c-representation from Eq.(8) into Eq.(7) taking into account 
that [21] 

OO 1 

e ikr dT = iTr ■ sgnk ■ e~ iak , (9) 

-oo T + a 

/oo 
\f(r)\ 2 dr = l. (10) 
-oo 

The microcausality requirement [22] implies that the field operators generating the field states belong- 
ing to the Hilbert state space when acting on the vacuum vector should either commute or anticommute 
if they are related to two spatially-like domains. The commutator of two field operators is known to be 
a distribution (see details in Ref. [22]). If one wishes to talk about local properties of the distribution, 
the test functions should possess certain properties (actually, they should belong to the space J{x) of 
infinitely smooth functions which vanish at infinity faster than any inverse polynomial). In other words, 
the states of a free field cannot have a finite support (i.e. to be zero outside a finite domain) which 
means that the states of a free field are fundamentally unrealizable. However, one construct the states 
which are arbitrarily strongly localized in space and vanish at infinity with the rate arbitrarily close to 
the exponential one (e.g. see Refs. [23-27]). In addition, the functions from T>(x) with finite support 
form a dense set in J{x) which means that any function from J(x) can be approximated with functions 
from T>(x) with any desirable accuracy. 

In the context of our one-dimensional model the non-localizability can be derived from the Wiener- 
Paley theorem [28] since the normalization condition (10) together with Eq.(7) means the square integra- 
bility of the amplitude in the ^-representation and imposes the restrictions on the asymptotic behaviour 
of the function /(r): 

f(r) = f°° f(k)e~ ikT dk, f°° |1 " l f (r 2 )ll dr < oo. (11) 

JO J-oo 1 + T 

Equation (11) implies that the function /(r) cannot have a finite support in r and cannot decay expo- 
nentially at infinity, although it can be arbitrarily strongly localized and possess decay rate arbitrarily 
close to the exponential law, for example 

/(r) oc exp {-ar/ln(ln...lnr)}, (12) 

where a take any value. 

For the reasons of convenience we shall first formulate the protocol for the states with finite support 
(since the functions from T>(t) form a dense subset and any function /(r) can be approximated with 
functions from T>(t) with any accuracy) and then introduce the necessary modification to account for 
the non-localizability of the states. 

Let the state /(r) have a finite support, supp/(r) = (—At, At) (At can be chosen to be arbitrarily 
small). The states are formed by only the vectors |t) belonging to the interval (—At, At) on the light 
cone: 

|V>0,1> = / T /(T)|T>dT®|eo,l>. (13) 
J-At 

In contrast to the non-relativistic quantum protocols which do not explicitly employ the spatio-temporal 
structure of the states and the state preparation effects are unimportant (to be more precise, the non- 
relativistic quantum mechanics allows an instantaneous preparation of any states from H, even those 



which are non-local in the position space, at any moment of time), the situation is quite different in 
the field theory. Preparation of a state requires access to a finite spatio-temporal domain (even if the 
state support is assumed to be finite). In the one-dimensional model the state preparation requires either 
the access to the spatial domain of size Ax = 2Ar if the state is prepared by a non-local source at 
a specified moment of time t or a finite time interval At = 2Ar/c if the state is generated by point- 
like source at point x. Therefore in the relativistic case the protocol can only be formulated after the 
system geometry is completely specified. The one-dimensional situation is the simplest one, since all the 
quantities here depend on a single variable r = x — ct. Bearing in mind that the actual experiments 
employ quasi-one-dimensional optical fiber systems, analysis of the one-dimensional model seems to be 
quite reasonable. 

Consider now the "stretched" states used in the protocols. These states consist of the two halves 
separated by the interval To on the light cone and can be written as 

|V>o,i(to)> = ^=J (f(r) + f(r - r ))\r))dr ® |e ,i>. (14) 

Here and below we adopt the normalization 

/oo roc 
\f(r)\ 2 dT= \f( T -r )\ 2 dT = l, supp/(r) n supp/(r - r ) = 0. (15) 
-oo J —oo 

Since the initial state support belongs to the interval (—At, At), the state preparation requires access 
to the domain (— At, At + To) on the light cone (either domain Ax = (—At, At + to) of the position 
space if the preparation is performed with a non-local apparatus at a specified moment of time or the 
time interval At = (—At, At + To) if the state is produced by a local source at point x). 

Consider now the individual measurements performed by user B over the quantum field states. The 
measurements are described by a partition of unity specified on the possible outcomes space defined as a 
set £1 = {t € (— oo, oo), i = 0, 1}: 



CO 



— oo 



M{dT))®{V + V l )= (16) 

' J°° dr e lkT \k}dk^j (jf° e- ik ' T (k'\dk'^ {Po + Pi) , (k\k') = 5{k - k') 

where \k) is a formal eigenvector with the specified k, and 

M(dr) = \T){r\dT, To = |eo)(e |, V\ = |ei)(ei|. 

We shall also need the description of the state propagation through the quantum communication channel 
from the domain controlled by user A to the domain controlled by user B. This propagation is described 
by a unitary translation of the state \ipo,i) along the light cone branch t = x — ct: 

Uch(T c h)\4>o,i) = \4>o,i,r ch ) = ~^f (f( T ~ T ch) + f(T -to- T ch ))))dT <g> |e ,i); (17) 

here t c ^ is the channel length. The state "extent" (2At + To) and the communication channel length 
(r c h) should satisfy the inequality T c h < tq + 2At, so that one can assume without loss of generality that 
T c h = (the channel length can be arbitrary until it does not exceed the state "extent"). 

The probability of obtaining an outcome by user B in the channel i (Vi) in the interval dr for the 
input state \tpj(ro)} is 

Pv{dr;i, j} = Tr {((M(dr)) V t ) |^(t ))<^(t )|} = k d \ {|/(r)| 2 + |/(r - t )| 2 } dr. (18) 

This expression describes the probability density for obtaining an outcome in one of the orthogonal 
(distinguishable) channels for (i = j = 0) and 1 (i = j = 1) in the interval dr. At the intuitive level 
such a measurement can be thought of as being realized with a very fast (formally with zero intrinsic 
time) photodetector operating in waiting mode. The measurement outcome is a random event occurring 
in the time interval dr with the probability density given by Eq.(18). 



The probability of detecting a state in the finite interval A(r) (for % = j) is 



Pr{A(r)}=/ Pr{dr;i,i} = U f \f( T )\ 2 dr+f |/(r - r )\ 2 dr I . (19) 
Ja(t) 2 [ja(t) Ja(t) J 

If the interval A(r) (accessible domain on the light cone) does not entirely cover the state support (for 
example, if only one half of the state is covered), the probability of obtaining an outcome is 1/2. However, 
if an outcome is obtained the states are uniquely identified because of the orthogonality of the channels 
Vo and V\. Therefore, in the time interval Ar < r < tq + At the probability of wrong state identification 
based on the measurement outcome is 1/4. Accordingly, the probability of correct identification is 3/4. 
On the other hand, for simple guessing the error probability is 1/2. 

It should be noted once again that the above measurement cannot be interpreted as a measurement 
which lasts for a finite time A(r): Every outcome occurs randomly at time t with the probability density 
(18). 

After the time tq + 2Ar elapses and the entire state is found in the domain controlled by user B, the 
values and 1 are uniquely identified because of the orthogonality of the corresponding states. 

Hence, propagation of the states with the maximum possible speed allows an explicit and natural 
implementation of the idea of providing by user A of only a part of information (part of a quantum state) 
on the chosen secret bit. Quantum nature of the state is important for the protocol since for a classical 
signal whose shape is described by the function f(r) with different polarizations eq or e\ the probability 
of correct identification is 1 (rather than 3/4) even if only a part of the signal is accessible. The correct 
identification probability of 3/4 in the quantum case is actually a consequence of the state normalization 
requirement. 

This result can also be derived in a somewhat different way allowing to clarify the peculiarity of 
the situations where only a part of the Hilbert state is accessible for measurements. Let us find the 
measurement minimizing the identification error in the problem of distinguishing between the two density 
matrices where the states are only partly accessible. The density matrices are written in the form 

Po,i = [±= (/ J/(r) + f(r - r )]|r)dr) (£W) + /V - r )](r'\dr^ } ® |e ,i>{e ,i| = (20) 

p(f)®p(0,l). 

We shall next derive an expression for the identification error occurring when trying to distinguish 
between the states po,i under the conditions where only a part of the entire space-time is accessible for 
measurements. Formally, the problem is reduced to the case where the domain A(r) is accessible for the 
measurements while the rest of the space-time (denoted as A(r) = (— oo, oo) — A(r)) cannot be accessed 
by available measuring apparatus. 

The measurement is described by the resolution of identity consisting of two terms. The first one is 
actually the identity operator in the subspace spanned by the basis vectors |r) belonging to the interval 
A(t), while the second term is the identity operator in the subspace spanned by the vectors form the 
inaccessible domain A(r) = (— oo, oo) — A(r): 

/ ® C 2 = /(At) ®C 2 + J(A(t)) ® C 2 = ^ ^ |r)(r|dr^ ®C 2 + ^ |r)(r|dr^J ® C 2 . (21) 

Suppose that the state po is produced for the measurements with the a priori probability ttq, while the 
state pi with the probability ir\ (tto + tt\ = 1). In the following we shall assume that ttq = ir\ = 1/2, i.e. 
or 1 are chosen by the user A with equal probabilities. 

Since only a part of the space-time is accessible for measurements (which automatically implies 
the restricted access to the Hilbert state space since the basis states are labeled by r), the total error 
contains two terms. The first one (P e (A(r))) corresponds to the situation where the measuring apparatus 
(photodetector) operated by user B did not fire (the outcome occurred in the inaccessible domain). The 
second term (P e (A(r))) describes the error in the state identification arising in the case where the 
measurement outcome took place in the domain accessible for user B. 



The probability of the event when the state was not detected by user B (his measuring apparatus did 
not fire) is 

P(A(r)) = Tr{(^ Po + mpx) (/(A(r)) «C 2 )} = ir p + tt iPi , p = Pi = P, (22) 

P=\ L [\f(r)\ 2 + \f(r-T )\ 2 ]dr. 
2 Ja(t) 

The probability po of the outcome in the inaccessible domain for the input state po produced with the 
specified a priori probability ttq is 

^OP / OQ ^ 
Po = : = tto, (23) 

7T p + 7Tip 

and, similarly, for p\ produced with the a priori probability n±, 

Pl= ^ =7Tl. (24) 

ir p + Trip 

The probability of error, i.e. the probability of the event when the state p\ is interpreted as state po, and 
vice versa, is 

P e (A(T)) =7T Pl+TTm. (25) 

If only one half of the state is located in the accessible domain (the support of either /(r) or f(r — To) 
belongs to the inaccessible domain), the probability of wrong identification for the case of the outcome 
occurring in the inaccessible domain calculated according to Eqs. (22-25) is P e (A(r)) = 1/2. 

In the general case the measurement minimizing the wrong identification probability is given for a 
binary resolving function by the identity resolution 

E + E 1 = J(A(r)) ® I C 2 = J(A(r)) (E + E{) , (26) 

where, in contrast to Refs. [29,30], the resolution is specified in the subspace restricted to A(r). The 
minimal error probability is found by the optimization with respect to all possible resolutions (see details 
in Refs. [29,30]): 

P e (A(r))= min (^{p^} + ^{p^}) , (27) 

where ttq and 7Ti are the probabilities of occurrence of density matrices po an d pi, respectively (in our 
problem 7To = tti = 1/2 are the probabilities of the preparation of and 1 by user A). 

Taking into account Eq.(26), the error probability can be reduced to the following form: 

P c (A(r)) = 7r TrM/)/(A(T))} + Tr{rP }, (28) 

r = mpi - ttqpq. 

Optimization of P e (A(r)) reduces to finding the minimum of TrjrPo} with respect to all possible oper- 
ators Eq. Since the domain accessible for measurements is restricted to the interval A(r), one has 

Tr{rP } = Tr A(T) {rP } = Tr A(T) {p(/)} ® Tr{(^ lP (l) - 7r p(0))P } = (29) 

|^/ A(r) [|/(r)| 2 + \f(r - r )| 2 ]dr| Tr{rP }. 
Since < E < 7(A(r)) (8) J C 2, 

Tr{rP } >Tr{r} =^ 7i (30) 

i 

The minimal possible error is determined by the negative eigenvalues ji of the operator T = 7Tip(l)— 7Top(0) 
[30]. The operator E should satisfy the conditions 

(li\Eo\ji) = 1, y t < 0, (31) 

(li\Eohi) = 0, 7l > 0, 



where | 7 j) are the eigenvectors of the operator T = X^7i|7i)(7i|- I n the basis {|eo), |ei)} the operator T 
has the matrix 

r = [ n 1 ° J , negative 72 = -vr = -1/2. (32) 



-7T 



Accordingly, the operator Eq is 



£b = /(A(t)) ® ^ ° J J, = /(A(r)) ® ^ J J J. (33) 
For the minimal error one obtains 

P e (A(r)) = / 2 (A(r))(vr + £ 7i ), (34) 

7i<0 

where the notation 

/ 2 (A(r)) = 1 / [|/(r)| 2 + |/(r - r )\ 2 ]dr. (35) 

is introduced. Finally, for the error probability in the case where an outcome occurred in the domain 
accessible for measurements one has 

1 ,1 1, 



P e (A(r)) = / 2 (A(r))(vr - vr ) = -(---) = 0, (36) 



/ 2 (A(r)) = -. 

At the intuitive level this result can be interpreted in the following way. Suppose that one has to 
distinguish between a pair of single-photon extended states with different (orthogonal) helicities. The 
correct identification probability is only unit if the entire states are accessible for the measurements 
(accordingly, the error probability is zero). In spite of the orthogonality of the basis vectors describing 
different helicities, the states cannot be reliably identified due to their spatial extent if they (their spatial 
amplitudes) are not entirely accessible. Physically, this is related to the fact that there exist no helicity 
states beyond the spatial degrees of freedom. Because of the normalization condition with respect to the 
spatial degrees of freedom the probability of firing of any measuring device employed by user B does not 
exceed 1 . Reliable distinguishing of the two states with even orthogonal helicities always requires a finite 
time since because of the restrictions imposed by special relativity the entire state cannot be accessed 
faster than the effective state "extent" divided by the speed of light. 

For a large number of measurements the total error is the relative frequency of wrongly identified 
states. The fraction (probability) of outcomes in the accessible domain is 

N(A(r)) = Tr{(^ Po + ir lPl )(I(A(r)) J c *)}> (37) 

and, similarly, the fraction of outcomes in the inaccessible domain is 

N(A{t)) = Tr{(^ Po + 7ripi)(J(A(r)) ® J c *)}- (38) 

The total error probability P e is the sum of the error occurring for the outcome taking place in the 
inaccessible domain multiplied by the probability of these outcomes and the product of the error occurring 
for the outcome taking place in the accessible domain and the probability of these outcomes: 

P e = P e (A(r)) • N(A(r)) + P c (A(r)) • N(A(r)). (39) 

When only halves of the states are accessible, one has 



ft(A(r)) = i JV(A(T)) = i «(A(t))=0, AT(A(r)) = i 



Accordingly, the correct identification probability is 3/4. 

The obtained result actually means the following. If user A prepares randomly and with equal 
probabilities either the state po or p\ and sends these states for measurements to user B, the probability 
of firing of the measuring device in one of the channels corresponding to or 1 is 1/2. If the measuring 
apparatus employed by user B gave an outcome, the state is reliably identified. However, if the apparatus 
did not fire, the user B can only guess which state was sent to him by user A. The probability for the 
apparatus not to fire is 1/2; in that case the correct guess probability is also 1/2. Hence for these 
events the net probability of correct identification is 1/2-1/2 = 1/4. The total probability of correct 
identification of the state sent by user A is thus 1/2 + 1/4 = 3/4. 

In this case the probability 1 — P e coincides with the probability of correct identification of the secret 

bit. 

This probability of correct identification is too high (substantially exceeds 1/2) for development of a 
valid protocol. The situation is radically changed if the secret bit is constructed as parity bit of N states. 
We shall see below that in this case the probability of correct identification of the parity bit exceeds 1/2 
by only an exponentially small value, i.e. practically coincides with the probability of simple guessing 
which is the worst strategy for user B. 

Let us now calculate the probability of the error of identification of the secret bit value when it is 
coded as parity bit of N orthogonal states. For the case where the entire state space is accessible for 
the measurements, the problem of the parity bit of a string of N bits each coded by one of the two 
non-orthogonal states was considered earlier in Ref. [32]. 

We shall first calculate the identification error for the outcomes occurring in the accessible domain. For 
a random string of N bits associated with the density matrix po,i described by 2^ possible combinations 
(2 N /2 of which are even and 2^/2 are odd) the problem is reduced to distinguishing between the two 
density matrices corresponding to even and odd strings: 

N 

PU = ^N 2 Pii ® Pw ® ■ • • PiN = ( 41 ) 

(110120-. .«jv)=0 

2 

■tfr W) ® P(f) ® ■ ■ ■ P(f)) ® H p(h)® p(i 2 )® ...p(i N ), 4 = 0,1, k = l,...N; 

(ii®j 2 e...iiv)=0 

N 

2 t * 

P 1 = 2N Ph <S> p i2 <S> ■ . . p iN = (42) 

(ii®i2®...ijv)=l 

2 x , 

2N W) ® P(f) ® ■ ■ ■ P(f)) ® 22 p(h)®p(i2)®---p(iN), 4 = 0,1 k = l,...N. 

(ii®i 2 ®...ijv)=l 

The measurement minimizing the identification error for the density matrices po and p\ is given by the 
identity resolution 

(I(A(t))®I c z)® N =h + h = I(A(r))® N ® (£b + A), E + Ei = I®2. (43) 

In that case the error probability is 

P e (A(r)) = vroTr {p (/(A(r)f" ® ig)} + Tr {f (/(A(r)f " <g> E ) } , (44) 

Accordingly, the minimal error is given by a formula similar to Eq.(28), and is determined by the negative 
eigenvalues (7$) of the operator 

f = (fiK)) N (ttip(I) - ttop(O)) = (7^(A)) iV r. (45) 



In the basis of vectors ordered into the even and odd (with respect to the sum of subscripts) sets, the 
operator T is written as 
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(46) 



Finally, the minimal error probability of the identification of the parity bit determined by N orthogonal 
states which are only partly accessible, is (ttq = 1/2) 



P e (A(r)) = (/ 2 (A)) 



N / 1 




(47) 



If only one half of each state is accessible (/ 2 (A) = 1/2), one has 

/1\ N (\ 1 2 N \ 
P.Wr))= - t-- w .-] = 0. 



(48) 



If the measurement outcome took place in the accessible domain, the identification error is zero because 
of the channel orthogonality. This formula should be understood in the following way. If all N outcomes 
occurred in the accessible domain, the error probability is zero because of the channel orthogonality. The 
same is true if the outcomes in the accessible domain took place for m states (in that case N in Eqs. (47,48) 
should be replaced by m). In other words, the states which resulted in measurement outcomes occurring 
in the accessible domain become reliably known to user B. 

However, the outcomes can also occur in the inaccessible domain. 

As the states gradually propagate into the domain accessible for the measurements performed by user 
B, / 2 (A) — ► 1, the error probability P e — ► 0. Any two orthogonal states are reliably distinguishable when 
each of them is entirely accessible for the measuring apparatus. 

Let us now calculate the probability of correct identification of the parity bit. The total number of 
binary strings of length N is 2 N . The outcomes can occur both in accessible and inaccessible domains. 
The total space of outcomes can be divided into two disjoint subsets. The first one corresponds to the 
event when all N outcomes occurred in the accessible domain. In that case the probability of correct 
identification of the parity bit is 1. However, the probability of this event for the case where only one 
half of each state is accessible / 2 (A) = 2~ N . 

The second subset corresponds to all other events when at least one outcome occurred in the in- 
accessible domain. The probability of all these events (when only one half of each state is accessible) 
is 



N-i 

]T C^ 2 (A) fc (l 

k=0 



N-l 



/ 2 (A)) 
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(49) 



For these events the probability of error in the parity bit identification is 1/2. Indeed, if user B has a 
string of length k (k < N — 1) whose parity is reliably known to him. However, the parity of the rest part 
of the string of length N — k corresponding to the outcomes in the inaccessible domain can be either odd 
or even with equal probabilities. Hence the parity of the full string consisting of N bits is known with 
the probability of 1/2, since the knowledge of the string of k bits does not help in any way in finding the 
parity bit of the full string. 

The total error in the parity bit determination is a sum of two contributions. The first one corresponds 
to the event when all outcomes took place in the accessible domain and the second one corresponds to all 
the rest events. Each contribution is a product of the probability of error in the parity bit identification 
and the probability of the event itself. One finally has 



PApar,ty)= l --(l-2- N )+Q-2- N 



i-i.a- 

2 2 



N 



(50) 



Accordingly, as long as only one half of each state is accessible to user B, the probability of correct parity 
bit identification by this user is 



P c (parity) = 1 - P e (parity) = - + - ■ 2~ N (51) 

and exceeds the simple guess probability by only an exponentially small value. 

Thus, during the time interval To (At < t < At + To) after the beginning of the protocol the user B 
has only exponentially small information on the secret bit. 

However, this scheme where the secret bit is coded as a parity bit of a string of N bit is still insufficient 
for the development of a useful protocol since it allows the user A to cheat with unacceptably high 
probability (to delay his choice of the secret bit without being caught by user B). 

To avoid this problem, each of N bits should be coded by a block of k identical bits (the number k 
will be specified below) which are randomly distributed over N ■ k channels. 

Finally, we shall give an expression for the probability of error when distinguishing between the two 
density matrices corresponding to and 1 for the case where the parity bit is coded by the blocks of 
identical bits (all of them are either or 1). In the protocol the secret parity bit is calculated over N 
bits each of which is represented by a block of length k. This block- wise representation of each bit is 
necessary for the detection by user B of possible cheating by user A. 

In that case the total number of binary string is 2 N ' k . When each and 1 is coded by blocks of length 
k, the number of odd and even strings among them is 



S odd , eV en = \ £ CW.l = 2 N - k (i-) £ cob™ cos (Nln) « 2™, (52) 

i.e. is actually equal to the number of different ways of distributing (N — I) ■ k units and / • k zeros (for 
< / < N) among N • k cells [30]. 

Note that if the position of each block was agreed upon in advance (i.e. the units and zeros from 
different blocks were not intermixed) the total number of possible odd and even strings would only be 
2^ which is exponentially less than 2~ N ' k (52) for large k. 

It will be important for the protocol that the rest N rest = 2 N ' k — S dd — S even <C 2~ N ' k strings do not 
belong to either even or odd string sets coded by blocks of length k. 

In the complete basis ordered with respect to odd and even block-wise states and other states (for 
definiteness we assume k to be even) the operator similar to Eq. (46) is 
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|eo) <8> |eo) • • • • • • |eo) <8> |e ) . . . 

other permutations of and 1 ... (53) 

k k 



|ei) <8> |ei) . . . . . . |ei) <g> \e\) . . . 



~>odd 



|e ) <8> |e ) . . . . . . |ei) ® |ei) . . . 

other permutations of and 1 ... (54) 

k k 



|ei) <g> |ei) . . . . . . |e ) <8> |e ) . . . 

the operator similar to Eq. (46) takes the form 




(55) 



where Is odd {I Seven) are urn t $odd x S dd (Seven x Seven) matrices, and 6 is the zero matrix of size 
N res t x N r est- 



The measuring operators E and E 1 in the same basis are written as 

( is nM o o\ 




^odd 





(56) 



E {] - / s' I . Ek = 

V o o // 

The probability of error in identification of the block-wise parity bit under the conditions that N ■ k 
outcomes took place in the accessible domain is 



P e (A M ) = (/'(A))"" I i - 1 E (-D | = »■ (W) 




The error probability is zero for all the states which gave the outcomes in the accessible domain. 

Let us now calculate the error in identification of the parity bit when coding with the blocks of length 
k is adopted. The outcomes can occur both in the accessible and in inaccessible domains. We shall 
first calculate the minimal number of outcomes which should occur in the accessible domain if the string 
parity is to be reliably identified. Since the direct calculation is rather difficult, we shall take advantage of 
the following approach (which is actually a straightforward modification of the Shannon typical sequence 
method [33,34]). For a moment we shall return to the situation where each bit is represented by a block 
of unit length, k = 1. Since the set of all possible strings contains Q = 2 N elements, the information 
carried by each particular string is / = log 2 |^| and (to within the rounding error) coincides with the 
number of binary symbols required to specify each string. If each symbol (in our case, firing of the 
detector employed by user B in the accessible domain) occurs with the probability p, the probability of 
the element identification is p 1 . 

For block-wise coding the number of all possible strings is given by Eq. (52) and the number of binary 
symbols required to identify a particular string is 

/ = i og2 {—[— E cosN ' k [j) cos ( Nl ^j = «w k )( N ■ fc )> ( 58 ) 

which yields the number of outcomes in the accessible domain required to identify the string parity. 
Accordingly, the probability of this event is (p = f 2 (A) = 1/2) 

p acc = p a(N,k)(N-k) = 2 -a(N,k)(N-k) _ ^ 

For these outcomes the error probability is zero. Accordingly, for the outcomes in the inaccessible domain 
we have 

p - 1 _ p - 1 _ o-a(N,k)(N-k). 

1 unacc — 1 1 acc — ± ^ , \ UKJ J 

the parity bit identification error in that case is 

P e (parzty) = \ ■ (l - 2'^^) + • 2 ^ N ^ N - k \ (61) 

Hence, the correct parity bit identification probability exceeds the simple guess probability by only an 
exponentially small value: 

P c {parity) = 1 - P e (parity) = - + 2~^ N ' k ^ N - k \ (62) 

Note that in the order of magnitude the number of block-wise coded strings with the zeros and units of 
all blocks randomly distributed over the entire string is equal to the total number of strings (~ 2 N ' k ) and 
each block- wise coded string looks almost like if the block length were k = 1. Therefore, the parity bit 
identification requires the knowledge of almost the full string (to within the correction factor of a(N, k) 
(52)). 

If the block position were fixed, there would be allowed strings and binary tests would be sufficient 
to identify the parity bit. However, the probability p of success in each such test is equal to the sum of 
probabilities of occurrence of 1 or 2 or ... k outcomes in the accessible domain 

p = ^c l 4w^) =l - 2 ~ k - (63) 



Accordingly, the probability of having N outcomes (the probability of reliable identification of the parity 
bit by user B when he has only access to the state halves) 

P aC c=p N = (l~2- k ) N (64) 

would be high (for comparable N and k). 

The only thing we should now to do is to demonstrate that after the time tq + At ~ To elapses and 
the states become accessible to user B the probability of cheating by user A tends to zero. To be more 
precise, we should demonstrate that user A cannot change his mind (modifying the chosen secret bit) 
after the protocol was started without being detected by user B with sufficiently high probability. 

In the protocol, N-k states are sent simultaneously randomly distributed over N-k channels. Possible 
cheating of user A is detected by user B with the help of a measurement described by the identity 
resolution of the form 

i® N - k ® jgT = (W) + W) + r±f N ' k , (65) 

where 

Vo,i(f) = I Jfir) + f(r - r )]|r)dr) (±= £W) + / V " roW\dr') |e ,i)<e ,i|, (66) 

v± = i0i c2 -v o (f)-v 1 (f). 

In each of N ■ k quantum communication channels only three measurement outcomes are possible cor- 
responding to Vo(f), Vi(f), and V±(f). If user A sends the correct states, the different outcomes 
probabilities are 

Pr{ Po , 0} = Tr{poW)} = 1, Pr{pi, 1} = Tr{p 1 V 1 (f)} = 1, (67) 

Pr{p , 1} = Tr{p ^i(/)} = 0, Pr{pi,0} = Tr{ Pl P (f)} = 0, 

Pr{po,i,T} = Tr{p ,iP±(/)} = 0, 

which means that all the outcomes should only occur with the unit probability in the channels Vo(f) and 
Vi(f) if user A employs the correct states. 

Any delay for a time longer than 2Ar introduced by user A means that he should employ the states 
which do not cover the front half of the correct extended state, i.e. user A begins the state preparation 
procedure after a time interval exceeding 2Ar has already elapsed after the protocol was initiated. For 
all such states p whose support does not cover the front half of the correct state the probability of the 
outcome in channels Vo(f) and Vi(f) does not exceed 1/2. Indeed, 

Tr{pV ,i(f)} = (68) 

1 /-At i-At 1 pto+At pto+At 

' / f(T)p(T,r')r(T')dTdr' + - / f(T)p(T,T')r(T')dTdr' < 

J -At * J to- At Jt -At 
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2 (2Ar)» Lllj^)W4T> < -, |p(r,/)|<l, 
if the support of p 

/ p(T,r')\r)(r'\dTdr', Tr{p} = / / <5 + (r - T')p(T,r')dTdT' = p( T ,r)dr = l, 

-ooJ— oo J —co J -co J —oo 

does not cover the front half of the correct state, 

suppp(r, t') n supp/(r - r ) = 0. 

Hence, in the ideal communication channel any delay of the state by user A results in the outcome 
probabilities in the channels Vo(f) and Vi(f) not exceeding 1/2. To be more precise, in every individual 
experiment, even for the states delayed for more than 2Ar, the measurement outcome can only occur 
in the channels Vo(f), Vi(f) and should never occur in the channel V±(f). The probability of such 
an outcome is 1/2. However, the probability of the event where in k experiments all the measurement 
outcomes for delayed states occurred in the channels Vo(f) and V\{f) only, and thus reproduce the 
correct statistics characteristic of the non-delayed states is as small as 2~ k . This circumstance will later 
be used in the protocol. 

Let us now formulate the protocol itself. 



3 The Bit Commitment protocol for finite support states in the ideal 
communication channel. 



• Before the protocol is started, the participant agree upon the states used (the localization interval 
At and the state shape /(r)), as well as the duration to of the protocol (the time during which 
user A retains the secret bit). In principle, time To can be chosen arbitrarily long, although this 
may present a difficult technical problem. The users choose also N and k. 

• User A chooses a secret bit which is the parity bit of a string consisting of N representatives 
b = J2iLi a [h i]> where a[i,j] is bit or 1, a representative of j'-th block (j is the number of the 
block consisting of k bits). All the bits in each block are identical. 

• At the moment when the protocol is started (this moment is also agreed upon by the users in 
advance) user A begins to prepare N • k stretched states consisting of two peaks (halves) which 
are allowed to propagate into N • k quantum communication channels as they are being formed. 
The states could also be sent through a single communication channel in series, although this 
would substantially increase the time required for the protocol implementation. Bearing in mind 
the above remarks, we assume that the channel length is zero which actually means that user B 
controls only his laboratory (vicinity of the point xb) and has no control over the rest space and the 
communication channel so that user A can in principle be located just at the threshold of the user 
B' laboratory. Simultaneously, user A can control only the vicinity of point xa where the states 
are prepared. 

The states from different blocks a[i,j] are sent through different channels at random. 

• User B can choose any moment of time from the interval At < t < tq + At to start the disclosure 
stage when user A should announce through a classical communication channels which state were 
sent in each quantum channel and identify the quantum channels belonging to each block. 

• User B performs the measurements described by the identity resolution (65-67). Although the states 
are orthogonal (and, consequently, reliably distinguishable), the non-local nature of the projection 
operators Vo,i implies that the reliable distinguishability (67) can only be achieved with the correct 
states if one has access to the entire state which requires time 2 At + To- Then user B compares 
the results of his measurements in each quantum channel with the data supplied to him by user 
A through the classical channel. For ideal quantum channels, the outcomes obtained in all the 
channels belonging to the same block should yield the identical results (all or all 1). User B 
abandons the protocol as soon as he finds a discrepancy between the results of his measurements 
and the data provided by user A for at least one of the quantum channel. 

Note that if user A acts in an honest way (sends the correct stretched states at the beginning of the 
protocol, i.e. the parity of the string consisting of N ■ k bits is indeed chosen at the very beginning 
of the protocol), no redistribution of the quantum channels among the blocks can change the parity 
bit since otherwise the sets of odd and even strings would have common elements. 

• If user A does not choose the bit value at the beginning of the protocol (to be more precise, 
if he chooses the secret bit value after the time At but, of course, before the disclosure stage, 
At < t < to + At) he will have to send the states different from |Y>o,i)- However, for any states 
different from the correct ones, the outcomes in each of the channels Vo,i will occur with the 
probabilities not exceeding 1/2. To modify the secret bit, user A should delay his choice in at least 
one of the blocks as a whole, i.e. he should delay at least k states. The probability of avoiding the 
detection of delay of k states by user B is then 2~ k (see Eq.(68)). 

• The probability for user B to have reliable information on the secret bit before he acquires access 
to the entire states does not exceed 1/2 + 2~ a ^ N ^ N ' k (see Eq.(62)). 

Hence, the protocol allows to implement the original idea of bit commitment scheme when one of the 
participants provides only part of information analyzing which the second participant can only extract 
exponentially small information on the secret bit value before the disclosure stage. At the same time, user 



A cannot change the chosen secret bit after the protocol is started (to be more precise, the probability 
of undetected modification of the chosen secret bit value after the protocol is started is exponentially 
small). 

The outlined scheme allows to implement an honest protocol with the probability not worse than 
1 — 2~ k which is exponentially close to unit for large k. 

4 The Coin Tossing protocol for finite support states in the ideal 
communication channel. 

Although the coin tossing protocol can be constructed on the basis of the bit commitment protocol, it is 
useful to formulate it explicitly. 

• Just as in the outlined bit commitment protocol, the participants A and B agree upon the states 
used. When the protocol is started, each of them sends to the other N blocks containing k states 
randomly distributed among N-k channels, the bits 6 a and bs chosen by users A and B, respectively, 
being coded as the parity bits of the strings consisting of N blocks. The users also agree in advance 
who is the winner if the final parity bit 6 = 6 a © 6# is or 1. 

• At an arbitrarily chosen moment of time r (—At < r < tq + At) one of the users, e.g. user A, 
announces for one half of all blocks through a classical channel which states were actually sent 
by him and identifies the blocks to which these states belong. After receiving these data, user B 
sends back to user A similar information for another half of his channels different from the channels 
disclosed by user A. Having obtained this information from B, user A discloses which channels 
belong to his still unrevealed blocks and the states that were actually sent through these channels. 
Then user B announces similar information about the rest of his channels. Since the channel length 
T ch < t~o, the exchange through the classical channel can be performed at the time when the users 
have access to only one half of each state. 

• Just as in the above bit commitment protocol, the user cannot determine the parity bit chosen by 
the other participant with the probability exceeding 1/2 until the states become fully accessible to 
him. 

• The users perform the measurements described by the identity resolution (65-67). Although the 
states are orthogonal (and, consequently, reliably distinguishable), the non-local nature of the 
projection operators Vq : i implies that the reliable distinguishability (67) can only be achieved with 
the correct states if one has access to the entire state which requires time 2 At + tq. 

• After the time tq + At elapses and the states become fully accessible to both users, each of them 
compares the results of his measurements in each channel with the classical information provided 
by the other user. The protocol is abandoned if a discrepancy is found in at least one channel. 

• Just as in the previous protocol, the probability for each user to obtain reliable information on the 
secret bit chosen by the other user before the states become entirely accessible, does not exceed the 
probability of simple guessing by an exponentially small value 2~ a ( N ' k ) Nk . 

As a result, an honest parity bit (lot) 6 = 6 a © bs arises with the probability exponentially close to 
unity (1 - 2- k ). 

Obviously, even the correct states are sent by both users, one of them can abort the protocol 
claiming the discrepancy between his measurement results and the classical information provided 
by the other user if the arising parity bit does not suit him. However, this situation lies beyond the 
formulated problem and should be solved by different means. 

Note that sending information through the classical channel is necessary to avoid the cheating strategy 
consisting in sending back the quantum states received from the other user ( "send back" strategy) . For 
example, one of the users can send no his own states at all and instead simply use a "mirror" to reflect 
back the states arriving from the other user. In that case the user (say, user A) which wins if the final 



parity bit b = © b B is zero can always cheat the other user since in this situation bA = b B and, hence 
b = b A © b B = b B © b B = 0. 

Disclosure through the classical channel of the data on only one half of the quantum states sent by 
each user is also required to avoid the "send back" strategy. Had one user (say, user A) announced the 
information on all the quantum states, the second user (user B) could employ the "send back" strategy 
in quantum channels and simultaneously send through another classical channel the data just received 
from user A since T c h < To- This strategy fails if only one half of all the quantum states are disclosed at 
first. 



5 The Bit Commitment protocol for unlocalized states in the ideal 
communication channel. 

So far we have considered the protocol employing the states with finite support (functions /(r) £ V(t)). 
The set of such functions forms a dense set in the space of functions describing the states of a free field 
(functions /(r) € J{t)). However, the field theory allows the states defined on the mass shell which 
are arbitrarily strongly localized and decaying with the rate arbitrarily close to the exponential law 
(/(r) oc e - QT / lnln - lnr ). Hence one can always choose the states in such a way that the measurements 
performed over them in a finite domain on the light cone r yield the net outcome probability arbitrarily 
close to unit, i.e. to make the contribution of the state tails at infinity arbitrarily small. To be more 
precise, the states (functions /(r)) and the measurement domain can be chosen in such a way that the 
probability of obtaining a result in the domain A(r) be 

Pr{A(r);M} = ^ { ( (/^ ^( dr )) ® I^XV-il j = \f(r)\ 2 dr = 1 - e"* - 1, (69) 

/oo 
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where £ can be arbitrarily large. Contribution from the state tails outside the domain (—At, At) is 



e"« 



= /r|>Ar l/(r)|2dT = Tr {((/r|>Ar- M(dT) ) l ^ )( ^ l f (70) 



To preserve the analogy with the case of finite support states we shall write the stretched state with 
non-compact support in the form 

l r°° 

\M = ^= j_Jf(r) + f(r - T )]\r)dT ® |e ,i), /(r) G J(r), (71) 

where function /(r) (/(r — To)), just as for the one-humped state (13) considered earlier, is strongly 
localized in the interval (—At, At) ((—At + To, At + To). The normalization condition yields 

-J \f(r)\ 2 dr=- | /(r _ To) |2 dT e -S (72) 

Z J -At ^ J-At+tq Z Z Z 



and 

\f \f{r)\ 2 dr+ l -j \f iT -r )\ 2 dr+ (73) 

^ Jt>|At| ^ JT+T >jAT| 

7y / [/*(t)/(t - to) + /(t)/*(t - T )]dT = e"«. 

Measurements performed over the stretched state in a finite window A(to) = (—At, To + At) yields 
a result with the probability 

Pr{A(T )};M} =TrU n^ T °M(dr) \ ®V ,i] = l-0(e^). (74) 



The latter term arises due to the overlapping of the tails belonging to the two halves of the state centered 
at r = and r = tq and does not exceed C?(e 

Thus the statistics of measurements performed over the stretched states should yield the results in the 
interval (—At, At + tq) with the probability 1 — C(e~^) — ► 1 exponentially close to unit. The probability 
of obtaining a count beyond this interval does not exceed 0(e~^) and can be made arbitrarily small by 
choosing appropriate /(r), At, and To- 

Preparation of a delocalized state with /(r) G J(t) formally requires an infinite time (if the state 
is generated by a point-like source) or access to the entire position space (if the state is prepared at a 
specified moment of time by a delocalized source). However, any realistic protocol should have a finite 
duration. To avoid the formal problems of that kind, it is convenient to argue in the following way as it 
is usually done in similar situations. User A controls the neighbourhood of point xa and adiabatically 
turns on the source (at t — > — oo) which generates the vector ipo,i( T o)) horn the vacuum state. The source 
is described by the action of an S(t, — oo)-matrix on the vacuum state (we do not consider the problem 
of experimental realization of this source) and the produced state 

|Y>o,i(t)) = S(t, -oo)|0> = f [/(t') + /(t' - -m)]\T f ))dr J ® |e ,i), (75) 

J — oo 

is sent into the communication channel as it is being formed. 

At the intuitive level this source can be thought of as an atomic system (an atom) with a suitable 
spectrum excited by a classical field with the appropriately chosen amplitude shape which is turned 
on adiabatically and emits photons into the communication channel (preparation of unusual one- and 
two-photon states is discussed, e.g. in Ref. [35]). 

User B performs measurements described by the identity resolution similar to Eq.(65): 

/oo 
\r)(r\dT, (76) 
-oo 

Po,i(A) = (77) 

/ 1 /-Ar+ro \ / 1 /"Ar+ro \ 

W2 J -At ^ r ) + /( r - r *H h^J_ Ar [f{T r ) + f(T'-T W\dT'UMM, 

and then 

V±(A) = I-P (A)-V 1 (A). (78) 
On the correct stretched states the measurement (76-78) yields the result with the probabilities 

Tr{p 0il P ,i(A)} = l-O(e-«), (79) 

Tr{ Po ,i7MA)} = 0(e"«). 

Similar to Eq.(68), for any states p which are not entirely concentrated in the sum of two intervals 
(—At, At) and (— At + To, At + To), the measurement (76-78) yields 

fAr i-At 



[ T [ T S + (t - t') P (t, T>)dTdT' = \- l e -*, (80) 

J -At J -At £ £ 

/At+tq /-Ar+ro 1 1 

/ 6 + (T-T>)p(T,T')dTdT'=---eS. 
-Ar+rn J-Ar+rn ^ Z 



rAT+To /-Ar+ro 1 1 

/ r ' ' ■ ' ' 

-Ar+ro ./-Ar+ro 

Hence, the delay of a state for more than 2At will result in the probability of obtaining a result on that 
state in the channel Vo,i drops from almost 1 (79) to almost 1/2 (80), 



Tr{pV ,i} = \- (81) 

Accordingly, the probability in the channel V± the probability rises from almost (79) to almost 1/2 
(80), 

Tr{pP ± } = \- l e -€. (82) 



Just as in the previous case, user A prepares N • k states and sends them into the communication 
channels. As long as only the halves of the states are accessible (At < t < At + To), the probability for 
user B to obtain information on the secret parity bit chosen by user A does not exceed 



P c (parity) « ± + Q - O(e^) 



a(N,k)Nk 



(83) 



The probability of delaying the choice by user A for at least one of the blocks consisting of k bits without 
being detected does not exceed 



The probability of successfully completing the protocol (when all N ■ k states produce the results in 
channels Vo,i) is 



can be made arbitrarily close to 1 by the appropriate choice of N, k, and £. 

6 Conclusions. 

Thus, the existence of maximum speed of quantum state propagation allows to develop the relativistic 
quantum bit and coin tossing protocols explicitly implementing the original idea of the protocol where one 
of the participants provides only part of information (part of quantum state) on the secret bit. However, 
the statistical nature of the measurement procedure in quantum mechanics does not allow (at least for 
the proposed protocol) to realize the honest protocol with the unit probability Nevertheless, the honest 
protocol can be realized with the probability arbitrarily close to 1. In addition, the fundamental non- 
localizability of the quantum field states also imposes restrictions on the probability of the realization of 
the honest protocol in a finite time interval. Nevertheless, the possibility of construction of arbitrarily 
strongly localized states allows to develop an honest protocol with the success probability arbitrarily 
close to 1 for any time To (time during which the bit secrecy is preserved). 

In contrast to the non-relativistic protocols where only the structure of the states in the Hilbert 
space matters, the proposed relativistic protocols explicitly involve the stages of the state preparation 
and propagation in the space-time between the two distant users. Since the spin and helicity states do 
not exist separately from the spatial degrees of freedom of a quantum system, accounting for the spatial 
degrees of freedom extends the possibilities for construction of quantum cryptographic protocols. 

It should be emphasized once again that the protocol is based on the orthogonal states. A non- 
zero error probability in distinguishing between the two orthogonal states arises due to the fact that a 
measurement can give no outcome at all (a photodetector will not fire, or the arrow of a classical device 
will not move) if the spatial domain accessible for the measurement does not "cover" the entire state. 
Therefore, the measurement can have three outcomes: the classical measuring device pointed to one of 
the channels Vq or V\, or did not change its state at all. If the device showed any particular result, the 
measured state is reliably identified. If the state is not entirely accessible, there is a non-zero probability 
for the device of not changing its state at all (showing no result at all), the larger the inaccessible part 
of the measured quantum state the larger this probability. In that case the observer can only guess what 
state he was dealing with (the state identification error in this situation being 1/2). 

Since the spin and helicity do not exist separately from the spatial degrees of freedom, the restriction 
of access to the position space automatically restricts the access to the Hilbert state space. It is even 
possible to have the situation when the system state is completely inaccessible (the state amplitude is 
identical zero in the domain accessible for the measurement). 

It should be noted that the considered situation is different from that discussed in Ref. [36] in 
connection with the analysis of Ref. [13] where a quantum cryptosystem based on orthogonal states was 
proposed. For a pair of orthogonal states of a composite system consisting of two subsystems a and b 
with the state space TC a <g> rib 




(84) 




(85) 



\ih) = a \Ma)) ® 1Mb)} + Po\Ma)) ® 1Mb)}, 



|^i) = ai \Ma)} ® \Mb)) +Pi\M<>)) ® 1Mb)), 
where the states ao,l and /?o,i are such that the states | V^o) and \tpi) are orthogonal 

(Vd|^i} = 0. 

If only one subsystem, e.g. H a , is accessible, the states of the other subsystem (b) are non-orthogonal 

Pi = Tr Wa {|V>i)(^i|}, = Tr Wa {|^ )(^o|}, Tr W(j {p • Pi} + 0, 

and, therefore, cannot be distinguished reliably. In our case the states remain orthogonal even after 
the restriction to a subspace and the absence of reliable distinguishability arises only due to the spatio- 
temporal structure of the states. 

The protocol can also be extended to a noisy channel [38] since the initial orthogonality of the states 
employed allows to employ the classical codes [37]. 

In the proposed scheme the protocol duration time ~ tq is defined by the effective "extent" of the 
states which for photons can be estimated from the frequency spectrum width. The minimum attainable 
spectrum width in the visible range in the ring optical fiber resonators [39] is Aw ~ 10 kHz, the effective 
state length being L pa c/Alu = 3T0 10 /10 4 = 3-10 6 cm (30 km). Accordingly, the time To ~ 1/Aw pa 10~ 3 
s. Although there exist no fundamental restrictions on making time to arbitrarily long (and, respectively, 
Alu arbitrarily small) this is very difficult technical problem. However, this circumstance does not matter 
for the Coin Tossing protocol, since the time To for getting an honest lot can be arbitrary. On the 
contrary, for the Bit Commitment protocol the time To is an important parameter since it determines 
the time interval during which the secrecy of the chosen bit preserved. This is a rather general situation 
in the experimental realization of various systems for transfer and processing of "quantum information" 
where experimental realization of the possibilities formally allowed by the laws of quantum mechanics 
today requires solution of extremely difficult technical problems. 

It should also be noted that the large-scale information transfer systems are based on optical fiber 
where the speed of signal propagation is somewhat lower than the speed of light in vacuum. However, 
this does not impose any restrictions since it is only necessary that the separation between the "halves" 
of the states used be larger than the channel length divided by the speed of light in the optical fiber. 

This work was supported by the Russian Fund for Basic Research (grant N 99-02-18127), the project 
"Physical foundations of quantum computer" and the program "Advanced technologies and devices of 
micro- and nanoelectronics" (project N 02. 04. 5. 2. 40. T. 50). 
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